DocumentCode :
621136
Title :
Trapping botnets by DNS failure graphs: Validation, extension and application to a 3G network
Author :
Bar, Arian ; Paciello, Antonio ; Romirer-Maierhofer, Peter
Author_Institution :
Forschungszentrum Telekommunikation Wien (FTW), Vienna, Austria
fYear :
2013
fDate :
14-19 April 2013
Firstpage :
393
Lastpage :
398
Abstract :
In the last years, botnets have become one of the major sources of cyber-crime activities carried out via the public Internet. Typically, they may serve a number of different malicious activities such as Distributed Denial of Service (DDoS) attacks, email spam and phishing attacks. In this paper we validate the Domain Name System (DNS) failure graph approach presented earlier in [1]. In our work we apply this approach in an operational 3G mobile network serving a significantly larger user population.Based on the introduction of stable host identifiers we implement a novel approach to the tracking of botnets over a period of several weeks. Our results reveal the presence of several groups of hosts that are members of botnets. We analyze the host groups exhibiting the most suspicious behavior and elaborate on how these participate in botnets and other malicious activities. In the last part of this work we discuss how the accuracy of our detection approach could be improved in the future by correlating the knowledge obtained from applying our method in different networks.
Keywords :
3G mobile communication; Internet; computer crime; computer network security; graph theory; DDoS attacks; DNS failure graphs; Distributed Denial of Service attacks; Domain Name System failure graph approach; botnet tracking; botnet trapping; cyber-crime activities; email spam; host identifiers; malicious activities; operational 3G mobile network; phishing attacks; public Internet; Algorithm design and analysis; Clustering algorithms; Electronic mail; IP networks; Monitoring; Servers; Superluminescent diodes;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Communications Workshops (INFOCOM WKSHPS), 2013 IEEE Conference on
Conference_Location :
Turin
Print_ISBN :
978-1-4799-0055-8
Type :
conf
DOI :
10.1109/INFCOMW.2013.6562863
Filename :
6562863
Link To Document :
بازگشت